Description
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.
Published: 2026-08-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP Manufacturing Integration and Intelligence (MII) includes a code injection flaw that allows an attacker with high privileges to submit crafted input to specific functions. The input is processed without adequate validation, permitting execution of arbitrary commands on the underlying operating system. This can compromise confidentiality, integrity, and availability of the MII application.

Affected Systems

The vulnerability affects SAP Manufacturing Integration and Intelligence (MII) implementations licensed under the SAP SE product line. Specific affected versions are not enumerated in the data, so the issue applies to all versions of SAP MII that have not yet remediated the input validation oversight.

Risk and Exploitability

The CVSS score of 9.1 signals a critical severity, and the EPSS score is not available, indicating that up‑to‑date exploitation probability is unknown. The flaw is not listed in the CISA KEV catalog. An attacker must have high privileges—typically distributed by SAP users or administrators—to leverage the vulnerability. Once authenticated, the attacker can execute arbitrary system commands, presenting a high risk to confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 11, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch referenced in SAP Note 3758900 to update SAP MII.
  • Restrict user privileges so that only trusted personnel have high‑privilege access to MII.
  • Enable or enforce input validation for the affected functionality to mitigate future injection risk.

Generated by OpenCVE AI on August 11, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap manufacturing Integration And Intelligence
Vendors & Products Sap
Sap manufacturing Integration And Intelligence

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.
Title Code Injection vulnerability in Manufacturing Integration and Intelligence
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Sap Manufacturing Integration And Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:33:21.798Z

Reserved: 2026-05-07T18:31:04.067Z

Link: CVE-2026-44758

cve-icon Vulnrichment

Updated: 2026-08-11T14:33:17.257Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T01:17:20.670

Modified: 2026-08-26T19:00:14.450

Link: CVE-2026-44758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:00:14Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')